Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts

Tuesday, July 21, 2015

A New Proactive Responsibility For Bankers in the Face of Cross Border Frauds

Let's face it - no one,, (whether an individual, a government or an organization)  is immune to or safe from a breach, an attack, a scam, a rootkit or a virus / APT or whatever you may call it. 
A crack is a crack is a crack is a crack (calling it a hack is sacrilege) 
And this is a global problem which is growing (exponentially) by the day, by the hour, minute, second and even nanosecond. Everyone has to face the threat, directly or indirectly, and no one ever knows when he/she will fall victim to an attack or an incident, and it really does not matter whether you are hyper intelligent or live inside Fort Knox. 
We do not have to go too far into history to see institutions like OPM, SONY, White House; global security organizations like RSA, The Hacking Team, HB Gary, NSA etc - the list is really big and includes banks etc.
In this global cybersecurity threat and crime maelstrom the Law Enforcement Agencies (LEA), Intelligence and Defense Agencies are first and foremost affected. They have a responsibility to investigate cybercrimes perpetrated across international borders, using sophisticated attack techniques or compromising insiders into malicious acts, voluntarily or involuntarily. Invariably while following cross-border leads, the LEA meets with insurmountable challenges and lengthy procedures (or red-tape even non-cooperation). And, if the request is to an unfriendly nation, the case might as well be closed and filed away!
Example challenges faced by LEA are in (1) following a money trail, (2) getting source IP information, (3) user name and address, etc. 
We will only look at "following the money trail" - in this case the victim may know the name of the bank where the funds were fraudulently transferred. However, when the bank is advised about the same they may not take any action until there is an order for the same in compliance with their locally applicable laws and regulations.  
However it is time for these officials, across the world, to raise a red flag at their end when they receive a communication directly from the victim (or victim country LEA).
Imagine if a bank manager gets a mail from a victim who informs about a fraud which has been perpetrated and where the funds have been transferred to that particular branch of the bank. The branch Manager may not be able to stop the account from operating but he/she can inform the local LEA about the suspect transaction. In addition, he/she can proactively guide the foreign victim and LEA about the quickest procedure to get the legally appropriate instructions for necessary action. 
The only (simple) reason why this bank manager in a foreign country should stand up and raise a red flag on the account, on the account holder and the transaction(s) is .... it can happen to him/her too. 
Yes, there is no guarantee that this bank branch, anyplace in the world, may fall victim to a fraud or a bank client may fall victim - then this manager will be running the same hoops as the victim / LEA who had connected earlier. 
This is not a call to disclose information, neither a call to work against the law or invade the account holder's privacy. It is not an aggressive look into transactions which is done through Risk Management and AML practices. In these changing times, it is an acceptance of responsibility by the banking professionals to set up a simple deterrent control. Criminals will slow down on using accounts in foreign lands once they are aware that ANY transaction can be notified to LEA proactively. 

Friday, November 6, 2009

Univ of Brighton research paper - bunchof lies !

I had forgotten this so called research paper but an article in the Economic Times prompted me to seek answers from the "researchers" at the Univ of Brighton.
These guys have a shallow paper based on heresy, misplaced / racist perceptions of the developing world and they pass judgement.

Then they do not have the decency to respond to any objection to their "paper" ... is it a problem to face up to your mistakes!

Phishing study: Bunch of lies
Kamlesh Bajaj / November 05, 2009, 0:46 IST

A team of researchers including professors of University of Brighton published a report in July 2009 titled “Crime online — Cybercrime and illegal innovation”. It was picked up by online news channels and quoted in news items to propagate lies about so-called cybercrimes in the business process outsourcing (BPO) industry of India. The report tries to present data from the annual reports of the Indian Computer Emergency Team, and Symantec in a way that suits its story, of India being a centre of cybercrimes and in general being a weak state. We want to set the record straight............... Read More


Now this is Dr Bajaj blasting them above and they deserve it.
I had written to them in August but they did not bother to reply, so now I am forced to put my email in the public domain:


Dear Messrs Howard Rush, Chris Smith, Erika Kraemer-Mbula and Puay Tang

I am writing to you with reference to your research report "Crime Online - Cybercrime and Illegal Innovation"

This report has been quoted as the source that states "India emerging as major cybercrime centre" and has obviously raised many doubts about the veracity of your study. A very alarming statement in your report says that cyber crime has increased 50 fold in India during the period three year period from 2004 - 07 and this is pure conjecture since you are referring to statistics for security incidents and not cyber crime and there is a BIG difference between these two.

A small search would have brought you to the Natoinal Criminal Record Bureau of the Government of India and you can easily get the cyber crime statistics.

While you are publishing your report in 2009 you are relying on news articles that date back to 2005 and your report uses these isolated incidents to irresponsibly pronounce judgement ! Sad, to say the least. Especially when you folks are living in the UK which is a "cybercrime-incident-a-day" country.

As I write to you I have this window open http://www.out-law.com/page-10309 which is not something to be proud about.

I am also taking the liberty of forwarding a digest of discussions (# 1171 of Aug 21) between people on the India Infosec mailing list relating to this report. Brickbats all around for you, sadly, for trashing the BRIC countries. Do join this list to know more about the opinions of the security community.


Your papes has been quoted here :

My final word here is that there are so many "experts" sitting in their lofty citadels who are driven by the need to generate copy. Information Security trends, issues etc cannot be judged on the basis of old articles and researchers must first understand the subtle differences in the jargon used in the business. For example, as every IS professional knows there is a big difference between problem management or incident management !

In any case, with the large number of white papers, content, research on the net it is important that one is cautious about what to accept as true :)



Thursday, December 13, 2007

This lover will take you for a ride !

A new threat on the Net ....... you may be cozy up with the wrong type of lover. A lover who does not exist and is only a computer program !! This robot will turn you on and get under your skin :)


Cyber lovers warned beware of flirtatious robots
Predatory program can attract 10 partners in 30 minutes
Sandra Rossi, 11/12/2007 15:58:04
Read the full story here

http://www.computerworld.com.au/index.php/id;1672098041;fp;;fpid;;pf;1

Internet users are being warned about a new malware trend involving the use of natural language dialogue systems that are already deployed within gaming technologies.

The software conducts fully automated flirtatious conversations in a bid to collect personal data from those seeking relationships online.

Monday, October 22, 2007

Weapons of Mass Destruction ? The next battleground

No one found the WMDs ! The reason is simple ... the search was in all the wrong places.

They do exist but not in the tangible world as we know them. The WMDs we have grown up with are the nuclear devices, the chemical weapons, the large armies, the terrorists. These are passe.

WMDs today are unseen, they are invisible bits and bytes that can travel over fiber optic across continents before you can blink. These bits and bytes, shaped by some 'beautiful' criminal mind into a virus, a trojan, a DOS to wreak havoc and bring terror to the doorstep of the common man.

Critical infrastructure like airports, dams, utilities, power and nuclear facilities, defence facilities are on alert against the risk of attack but with barriers and para-military forces the threat is mitigated. What about the WMD attack - the attack which comes stealthily via the internet in the form of trojans, viruses, rootkits, web-bots etc. An attack which can paralyze the airport or can shutdown the nuclear facility.

Webface defacements, hacking, data theft and such IT crime is commonplace today and we have new reports daily - globally. So it is easy for a terrorist to construct the WMD and let it loose for destruction.

So how do we search and control those evil designs. The answers may be in a reorientation of education at all levels. By the inclusion of ethics in system design and development, in the use of technology. Or will it be necessary for system development to be licenced and controlled by governments as is the case with the manufacture of nuclear and conventional weapons.

Recent events in Estonia have shown what the WMD can do, and we do not know whether the hills of Kandhar have classes in computer technology after the wannabe terrorist has finished target practice and the indoctrination lecture for the day.

Thoughts to ramble on, and yes it is a terrifying thought but what if it was another 'Live Free Die Hard' scenario.